aboutcode-org / aboutcode-org/dejacode

BUG: Packages being created with inadequate PURL data

未關閉
#275 2 則留言 0 個 reaction 已指派 3 人 已被 @DennisClark 認領 在 GitHub 檢視
bug HighPriority integration PackageSet
主要語言
Python
星號
50
分支
27
平均合併
4 小時 51 分鐘
30 天內合併 PR
11

描述

This problem actually is associated with multiple AboutCode projects, but the impact is most apparent to the DejaCode user. A recent import of an SBOM to a product in DejaCode resulted in the creation of 3 different package definitions for `pkg:github/pypa/pip@20.3.1` each with a different download URL. A subsequent search for `pip@20.3.1` turned up 2 older package definitions for `pkg:pypi/pip@20.3.1` each with a different download URL. We don't have a problem of duplicate packages here, but the PURLs are not well defined and should contain additional details to differentiate them:

* The 2 pypi packages should have a file_name qualifier.
* The 3 github packages should have a subpath value.

Screenshot of the 5 pip@20.3.1 packages attached.

Image

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。